CVE-2025-13797 is a critical command injection vulnerability affecting the ADSLR B-QE2W401 250814-r037c firmware, specifically within the del_swifimac parameter of the /send_order.cgi file. This remote vulnerability carries a CVSS score of 9.8, indicating a high risk of complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, public exploit code is available, and the vendor has not responded to disclosure. Community discussion is minimal, and there is no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 250814-r037cCPE matchmatch criteria | cpe:2.3:o:adslr:b-qe2w401_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.